CVE-2019-1460
published 2020-01-24CVE-2019-1460: A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages, aka 'Outlook for Android Spoofing…
PriorityP421medium4.6CVSS 3.1
AVNACLPRLUIRSUCLILAN
EPSS
1.44%
70.3th percentile
A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages, aka 'Outlook for Android Spoofing Vulnerability'.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_outlook_for_android | — | — |
| msrc | microsoft_outlook_for_android | — | — |
CVSS provenance
nvdv3.14.6MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_msrc4.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7889-wv3h-p95v: A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages, aka 'Outlook for Android
ghsa_unreviewed·2022-05-24
CVE-2019-1460 [LOW] GHSA-7889-wv3h-p95v: A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages, aka 'Outlook for Android
A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages, aka 'Outlook for Android Spoofing Vulnerability'.
Microsoft
Outlook for Android Spoofing Vulnerability
vendor_msrc·2019-11-12·CVSS 4.6
CVE-2019-1460 [MEDIUM] Outlook for Android Spoofing Vulnerability
Outlook for Android Spoofing Vulnerability
Description: A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message to a victim.
The attacker who successfully exploited this vulnerability could then perform cross-site scripting attacks on the affected systems and run scripts in the security context of the current user.
The security update addresses the vulnerability by correcting how Microsoft Outlook for Android parses specially crafted email messages.
Android App: Android App
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:N/A
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-01-24
Published